Last updated: 7 May 2026
This Data Processing Agreement ("DPA") forms part of the Terms of Service between SM Worx Group Ltd, trading as Portal Worx, a company incorporated in England and Wales under company number 17223018 ("Processor", "we", "us"), and the organisation subscribing to the Portal Worx platform ("Controller", "you", "your").
This DPA applies to the processing of personal data by Portal Worx on behalf of the Controller in connection with the provision of the Service. It is designed to meet the requirements of the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, the Protection of Personal Information Act 4 of 2013 of South Africa (POPIA), the EU General Data Protection Regulation (GDPR) where applicable, and other applicable data protection laws.
By subscribing to the Service, you accept this DPA. If you are entering into this DPA on behalf of an organisation, you represent that you have the authority to bind that organisation.
The Controller (your organisation) determines the purposes and means of processing Personal Data within the Service. As a Controller, you are responsible for:
Portal Worx acts as a Processor, processing Personal Data only on behalf of and under the documented instructions of the Controller. As a Processor, we are responsible for:
Personal Data processed through the Service may relate to the following categories of Data Subjects:
The following categories of Personal Data may be processed:
Personal Data is processed for the following purposes:
Personal Data will be processed for the duration of the Controller's subscription to the Service. Upon termination or expiry of the subscription, data will be retained and deleted in accordance with Section 10 of this DPA and our Privacy Policy.
The Processor implements the following technical and organisational measures to protect Personal Data, in accordance with GDPR Article 32, UK GDPR Article 32, and POPIA Section 19:
The Controller authorises the use of the following Sub-Processors. Each Sub-Processor processes data only for the specific purposes described:
| Sub-Processor | Purpose | Location | Data Processed |
|---|---|---|---|
| Amazon Web Services (AWS) | Cloud hosting, database, file storage, content delivery, email delivery | Global (multiple regions) | All Service data |
| Stripe, Inc. | Payment processing | United States | Billing and payment information |
| Cloudflare, Inc. | Bot protection (Turnstile) during account registration | Global | Device interaction signals, IP addresses |
| Google LLC | Location display (Maps API) | United States | Project location coordinates and addresses |
| Anthropic, PBC | AI-powered features — project summaries, report-template drafts, and category / folder name suggestions (optional) | United States | Project metadata (names, descriptions, dates, activity entries) and the names of assigned team members and activity authors. Where the customer opts in, also report content and project message content. No email addresses, passwords, billing data, or document/image file content |
Each Sub-Processor is bound by a written agreement that imposes data protection obligations no less protective than those in this DPA. The Processor remains fully liable to the Controller for the performance of each Sub-Processor's obligations.
The Processor will notify the Controller at least 30 days before engaging a new Sub-Processor or making material changes to existing Sub-Processor arrangements. Notification will be provided by updating this DPA and notifying the Controller by email.
The Controller may object to a new Sub-Processor on reasonable data protection grounds within 14 days of receiving notification. If the objection cannot be resolved, either party may terminate the affected Service component.
The Processor will assist the Controller in fulfilling its obligations to respond to data subject requests, including:
The Processor will respond to Controller requests for assistance with data subject rights within a reasonable timeframe, and in any event within the timeframes required by applicable law.
The Processor will notify the Controller without undue delay, and in any event within 48 hours, upon becoming aware of a Data Breach affecting the Controller's Personal Data. The notification will include:
Following a Data Breach, the Processor will:
The Controller is responsible for notifying the relevant supervisory authority (within 72 hours under GDPR, or as soon as reasonably possible under POPIA) and affected Data Subjects where required. The Processor will provide reasonable assistance.
Personal Data may be transferred to and processed in countries outside the Controller's jurisdiction, including countries where our Sub-Processors operate.
Where Personal Data is transferred from the EEA, the UK, or South Africa to a country that has not been recognised as providing an adequate level of data protection, the Processor ensures that appropriate safeguards are in place:
Personal Data is retained for the duration of the Controller's subscription. Deleted items (projects, documents, reports) are held in a 30-day trash recovery window before permanent deletion. User accounts can be deactivated or deleted by organisation administrators at any time.
Upon termination of the subscription:
When individual user accounts are deleted, their Personal Data is anonymised rather than simply removed. This includes replacing email addresses with pseudonymous identifiers, clearing profile information, deleting profile pictures from storage, and scrubbing personal data from email and activity logs. Audit trail records are preserved in an anonymised form for security and compliance purposes.
Direct messages between users within an organisation are retained for the lifetime of the sending user's account. When that account is permanently deleted, every direct message body authored by the deleted user is overwritten in-place with a placeholder so the original content is no longer recoverable; recipients see a “Message removed” placeholder in place of the original content. Recipient copies of their own outgoing messages are retained as part of the recipient's own data — they are not deleted as a side-effect of the sender's account deletion.
Senders can also delete individual direct messages they sent at any time. This is a hard delete on both sides of the conversation — the message disappears from both the sender's and the recipient's view in real time. Recipients cannot delete messages sent by another user. Together these two mechanisms satisfy GDPR Article 17 (right to erasure) for the direct-message surface.
The Processor will make available to the Controller all information necessary to demonstrate compliance with the obligations set out in this DPA. This includes:
Audits will be conducted at the Controller's expense and will not unreasonably interfere with the Processor's business operations. The Controller may exercise its audit rights no more than once per calendar year, unless required by a supervisory authority or in the event of a Data Breach.
Each party's liability under this DPA is subject to the limitations and exclusions set out in the Terms of Service. Nothing in this DPA limits either party's liability for breaches of data protection law to the extent that such liability cannot be limited under applicable law.
This DPA takes effect when the Controller subscribes to the Service and remains in force for the duration of the Processor's processing of Personal Data on behalf of the Controller. The obligations in this DPA that relate to the protection and deletion of Personal Data will survive termination.
This DPA is governed by the laws of England and Wales, without prejudice to the mandatory data protection laws applicable to the Controller in its jurisdiction (including the UK GDPR, EU GDPR, POPIA, or other applicable data protection laws). The courts of England and Wales shall have exclusive jurisdiction, save that nothing in this clause prevents either party from seeking injunctive or equivalent urgent relief in any competent court.
We may update this DPA from time to time to reflect changes in our processing activities, Sub-Processor arrangements, or applicable law. Material changes will be communicated to the Controller via email at least 30 days before taking effect.
For questions about this Data Processing Agreement or our data protection practices, please contact us: